REDHAT-BUG-737787: Low severity wireshark vulnerability
A large loop in the OpenSafety dissector could cause a crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This affects versions 1.6.0 to 1.6.1 and has been fixed in version 1.6.2
Reference: http://www.wireshark.org/security/wnpa-sec-2011-12.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-737787?
The severity of REDHAT-BUG-737787 is high due to the potential for crashing Wireshark through malformed packets.
How do I fix REDHAT-BUG-737787?
To fix REDHAT-BUG-737787, update Wireshark to version 1.6.2 or later.
What versions of Wireshark are affected by REDHAT-BUG-737787?
Versions 1.6.0 to 1.6.1 of Wireshark are affected by REDHAT-BUG-737787.
What causes the issue in REDHAT-BUG-737787?
The issue in REDHAT-BUG-737787 is caused by a large loop in the OpenSafety dissector.
Can REDHAT-BUG-737787 be exploited remotely?
Yes, REDHAT-BUG-737787 can potentially be exploited remotely by injecting a malformed packet.